CVE-2019-10466

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10466
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10466.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10466
Aliases
Published
2019-10-23T13:15:10Z
Modified
2024-09-03T02:22:24.428534Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

References

Affected packages

Git / github.com/jenkinsci/fireline-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/fireline-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Fireline_Plugin-1.*

Fireline_Plugin-1.4.20

fireline-1.*

fireline-1.0
fireline-1.3
fireline-1.4
fireline-1.4.1
fireline-1.4.21
fireline-1.4.22
fireline-1.4.3
fireline-1.4.4
fireline-1.4.4.2
fireline-1.4.40
fireline-1.4.41
fireline-1.4.42
fireline-1.4.43
fireline-1.4.60
fireline-1.4.61
fireline-1.4.80
fireline-1.4.81
fireline-1.4.82
fireline-1.4.83
fireline-1.4.84
fireline-1.4.90
fireline-1.4.91
fireline-1.5.0
fireline-1.5.1
fireline-1.5.10
fireline-1.5.11
fireline-1.5.12
fireline-1.5.13
fireline-1.5.14
fireline-1.5.15
fireline-1.5.16
fireline-1.5.17
fireline-1.5.18
fireline-1.5.2
fireline-1.5.3
fireline-1.5.4
fireline-1.5.5
fireline-1.5.6
fireline-1.5.7
fireline-1.5.8
fireline-1.5.9
fireline-1.6.18
fireline-1.6.2
fireline-1.7.0
fireline-1.7.2